All fingerprints
Network

WebRTC leak

UDP candidate gathering bypasses HTTP proxies and can reveal your real public and local IP.

Read viaRTCPeerConnectionICE candidates (STUN)

What it is

WebRTC lets pages open peer-to-peer connections for calls and file transfer. To connect, the browser asks a STUN server "what address do you see me from?" — and hands the answer to the page.

How websites read it

const pc = new RTCPeerConnection({ iceServers: [{ urls: 'stun:stun.example.net' }] });
pc.createDataChannel('x'); pc.createOffer().then((o) => pc.setLocalDescription(o));
pc.onicecandidate = (e) => console.log(e.candidate?.candidate); // "... srflx ... 198.51.100.24"

No permission is needed for candidate gathering. Server-reflexive (srflx) candidates carry your public address; host candidates carry LAN addresses, masked behind mDNS names in modern browsers.

Why it identifies you

A proxy configured in the browser only covers HTTP. STUN packets are plain UDP: they leave through your real connection and come back with your real IP.

How risk-control systems use it

Sites compare the WebRTC address with the address the HTTP request came from. A mismatch is one of the highest-confidence proxy signals — it needs no database, just two strings.

Common mistakes

Disabling WebRTC entirely (a hole where a value should be); leaving the real IP visible; extensions that block STUN but not TURN.

Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.

How Mango Browser handles it

Custom

Modes: off, auto (replace with the proxy exit IP), manual, real, disable UDP. Auto is the default — WebRTC keeps working and agrees with the HTTP IP.

Check yours

Jump to this signal in your scan results.

Open my results

Related fingerprints

Guides that use this signal